Two CVEs were published against oauthlib affecting all 3.x releases:
- CVE-2026-49265 -- Timing attack vulnerability in PKCE
code_verifier comparison (CWE-208)
- CVE-2026-49264 -- Unsafe JSONP callback injection in
RevocationEndpoint
Both are fixed in oauthlib 4.0.0.
The dependency chain here is:
kubernetes → requests-oauthlib → oauthlib>=3.0.0
requests-oauthlib declares oauthlib>=3.0.0, which allows resolvers to land on the vulnerable 3.x line. The upstream fix is requests/requests-oauthlib#577, but that project is slow-moving.
The same protective pattern was used before in #2016 -- adding a direct oauthlib pin to requirements.txt. A PR with the one-line fix is attached.
Once requests/requests-oauthlib#577 merges and a new requests-oauthlib release ships with the raised lower bound, this pin can be removed (same as #2434 cleaned up the previous one).
Two CVEs were published against
oauthlibaffecting all 3.x releases:code_verifiercomparison (CWE-208)RevocationEndpointBoth are fixed in oauthlib 4.0.0.
The dependency chain here is:
requests-oauthlibdeclaresoauthlib>=3.0.0, which allows resolvers to land on the vulnerable 3.x line. The upstream fix is requests/requests-oauthlib#577, but that project is slow-moving.The same protective pattern was used before in #2016 -- adding a direct
oauthlibpin torequirements.txt. A PR with the one-line fix is attached.Once requests/requests-oauthlib#577 merges and a new
requests-oauthlibrelease ships with the raised lower bound, this pin can be removed (same as #2434 cleaned up the previous one).